svn commit: r251088 - head/crypto/openssh
Dag-Erling Smørgrav
des at FreeBSD.org
Wed May 29 00:19:59 UTC 2013
Author: des
Date: Wed May 29 00:19:58 2013
New Revision: 251088
URL: http://svnweb.freebsd.org/changeset/base/251088
Log:
Revert a local change that sets the default for UsePrivilegeSeparation to
"sandbox" instead of "yes". In sandbox mode, the privsep child is unable
to load additional libraries and will therefore crash when trying to take
advantage of crypto offloading on CPUs that support it.
Modified:
head/crypto/openssh/servconf.c
Modified: head/crypto/openssh/servconf.c
==============================================================================
--- head/crypto/openssh/servconf.c Wed May 29 00:18:12 2013 (r251087)
+++ head/crypto/openssh/servconf.c Wed May 29 00:19:58 2013 (r251088)
@@ -298,7 +298,7 @@ fill_default_server_options(ServerOption
options->version_addendum = xstrdup(SSH_VERSION_FREEBSD);
/* Turn privilege separation on by default */
if (use_privsep == -1)
- use_privsep = PRIVSEP_ON;
+ use_privsep = PRIVSEP_NOSANDBOX;
#ifndef HAVE_MMAP
if (use_privsep && options->compression == 1) {
More information about the svn-src-head
mailing list